Security Overview
Last updated October 8, 2026. Questions about this document: sammooney@fulleleven.com.
Tenant and role boundaries
Organization data access is scoped to an organization context and database row-level policies. Routes check the user’s role before returning protected data or accepting a change. Restricted safety and medical details receive narrower access and read auditing.
Data protection
Designated sensitive fields are encrypted at rest by the application. Payment credentials are handled by the payment provider. Audit and financial records are retained or anonymized according to their documented rules rather than silently erased.
Development and incident response
Development and automated tests use fake messaging and payment adapters. Production deployment, monitoring, key management, backups, and incident response depend on operator configuration and must pass the launch checks before release.
Report a concern
Organization users should contact their administrator about account or data access concerns. Operators should follow the security disclosure and incident response procedures in the repository’s security documentation.